Entries from June 2007

Red Hat Security Update: mod_perl

Continuing on Monday’s mod_perl security update for Red Hat Enterprise Linux 2.1, Red Hat announced one new security update this morning.
RHSA-2007:0396 Low: mod_perl security update
This security update addresses one vulnerability in the mod_perl packages for Red Hat Application Stack v1 for Enterprise Linux 4. A remote attacker requesting a carefully crafted URI can cause [...]

Categories: Security Updates

Sun Security Update: Solaris 10 BIND

Sun Microsystems announced a new security vulnerability affecting BIND for Solaris 10 on SPARC and X86 platforms. A vulnerability in DNSSEC could allow an attacker to cause the BIND server process to exit resulting in a Denial of Service (DoS)(CVE-2007-0494). Although Sun has made patches available, it is advisable to run BIND without [...]

Categories: Security Updates

Allowing DHCP Option 82 in Cisco DHCP Relay Agents

If you are using your Cisco Catalyst switches to insert DHCP Option 82 information and you are also using your Cisco routers as DHCP relay-agents (via ‘ip helper-address’), you’ll notice right away that your Option 82 enabled DHCP requests are not being forwarded by your routers.
As a security measure, Cisco IOS will not forward DHCP [...]

Categories: Networking

Red Hat Security Update: mod_perl

Red Hat announced one new security update this morning.
RHSA-2007:0486 Moderate: mod_perl security update
This update fixes one vulnerability in the mod_perl package for Red Hat Enterprise Linux 2.1. An attacker can use a request a carefully constructed URI from a server employing the Apache::PerlRun module to cause resource consumption resulting in a Denial of Service [...]

Categories: Security Updates

Sun Security Updates: StarOffice, FreeType

Sun Microsystems recently announced two new security updates.
#102917: StarOffice / StarSuite
This update addresses one vulnerability in StarOffice / StarSuite 6, 7 and 8 for Solaris, Linux, and Windows. Due to a vulnerability in the way StarOffice / StarSuite handles RTF documents, a remote attacker could execute arbitrary code on the system (CVE-2007-0245). [...]

Categories: Security Updates